LWA-2026-7945 MAL-2026-11628 ↗ confirmed malware

@onereach/si-a-button@0.0.5

Malicious code in @onereach/si-a-button (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The preinstall hook (node setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a 727KB file (math_init.js) at install time. math_init.js is heavily obfuscated with a custom base85 string-table encoder, so its actual behaviour is not readable from source. The package is a Vue button component whose shipped component code (lib/) does not require Bun or any runtime, so the install-time download-and-execute of an opaque obfuscated payload is unrelated to the package's stated purpose. The obfuscated payload's network and file activity could not be determined from static analysis.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:16 PM
analyzed
Aug 4, 2026, 01:53 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.